The two terms sound similar enough that they get used interchangeably in conversations where precision actually matters, and that's worth correcting before it causes confusion in an architecture diagram or a vendor evaluation. Continuous Authentication and CAEP, the Continuous Access Evaluation Profile, do different jobs in the same problem, and neither one does the other's.
Continuous Authentication is the missing signal. It answers a specific question, continuously, for as long as a session is active: does the person operating this session still match the identity that authenticated it? Twosense generates that signal from behavioral data, typing rhythm and interaction patterns compared against a model built for the authenticated user, and it flags a behavioral mismatch when the two stop lining up.
CAEP broadcasts that trust signal in real time. It doesn't generate a judgment about identity or risk on its own, it standardizes how a judgment that's already been made, by Continuous Authentication or by any other system capable of producing one, gets communicated to the platforms that need to act on it. CAEP is what lets a behavioral mismatch detected by Twosense reach an identity provider or an EHR's access controls without custom integration work for every pair of systems involved.
Then there's a third job that neither continuous authentication or CAEP does: orchestration. Once a signal exists and has been broadcast, something still has to decide what happens next according to policy and subsequent enforcement. Reauthenticate the user, restrict what they can see, terminate the session, alert the security team, are all possible and that decision is tied to whatever policy engine or application which receives the CAEP event. Continuous Authentication doesn't make that call. CAEP doesn't make that call. However, they both feed the system that does and are essential in creating the full continuous identity posture.
Put together, the architecture reads as three distinct jobs: Continuous Authentication decides whether the identity behind a session is still trustworthy, CAEP broadcasts that decision to the systems that need to know, and a policy orchestration engine that decides what those systems do about it. That combination, evaluating trust continuously and acting on it automatically, is what the industry has started calling continuous identity. It's an umbrella term, not a single product, and health systems security teams evaluating vendors in this space should expect most of them to broadcast and enforce reasonably well. The missing signal, the part that actually confirms who's behind the keyboard, is where the gap usually is. Health systems security teams evaluating this space don't need to pick one of these instead of the others. They need to understand that all three are required, and that none of them substitutes for infrastructure the organization already runs.